← Back to overview

The Mirage2FA campaign has been active from 2024 to 2026, targeting Microsoft 365 accounts across thousands of companies in the US and EU. The campaign leverages a commercial phishing-as-a-service (PhaaS) toolkit that abuses legitimate Microsoft 365 login flows to bypass two-factor authentication. According to ANY.RUN research, approximately 4,500 companies have been affected, with 48% of targeted email addresses potentially compromised. The majority of affected organizations are US-based. Mirage2FA represents a significant threat due to its ability to circumvent MFA protections, a security control widely relied upon by enterprises. The commercial nature of the toolkit suggests it is being offered to multiple threat actors, amplifying its reach and impact.

Technical details

Mirage2FA is a commercial Phishing-as-a-Service (PhaaS) toolkit active from 2024 to 2026 that targets Microsoft 365 accounts using Adversary-in-the-Middle (AiTM) techniques. The toolkit abuses legitimate Microsoft 365 login flows to bypass two-factor authentication (2FA/MFA). Attackers steal both passwords and session cookies, enabling them to hijack authenticated Microsoft 365 sessions and access SSO-connected services without triggering MFA challenges. The campaign has potentially compromised 48% of targeted email addresses and is linked to 4,532 unique organization email domains. Over 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass were uncovered. Technical indicators include recurring loaders, encoded data, suspicious WebSocket activity, fake Microsoft 365 login pages, and malicious redirects. The US accounts for 63.7% of victims, with additional activity observed in India, Singapore, the UK, Canada, Saudi Arabia, and South Africa. Most targeted industries include technology, manufacturing, and education. Once a session is hijacked, attackers can conduct impersonation, fraud, and further lateral movement through SSO-connected applications and internal workflows.

Mitigation steps

1. Adopt phishing-resistant authentication methods (e.g., FIDO2/hardware security keys) to replace traditional MFA that can be bypassed by AiTM attacks. 2. Implement stronger session controls, including shorter session token lifetimes and continuous access evaluation. 3. Treat session theft as a full identity incident: revoke compromised sessions and tokens immediately rather than relying solely on password resets. 4. Investigate all activity tied to affected identities, not just the initially compromised account. 5. Integrate sandboxing tools to safely analyze suspicious URLs, attachments, and phishing pages before they reach users. 6. Monitor for suspicious WebSocket activity, encoded scripts, and redirects associated with fake Microsoft 365 login pages. 7. Use real-time Threat Intelligence Feeds to track evolving attacker infrastructure and complement behavioral detections. 8. Pivot from individual IOCs (suspicious URLs, domains, IPs, files) to uncover related infrastructure and broader campaign connections using Threat Intelligence Lookup. 9. Train SOC teams to investigate Mirage2FA activity beyond individual IOCs by examining recurring loaders and related infrastructure. 10. Integrate behavioral detection tools into existing SOC workflows for earlier identification of phishing and AiTM campaign behavior.

Affected products

  • Microsoft 365
  • Microsoft 365 SSO-connected services

IOC's

Fake Microsoft 365 login pages, Suspicious WebSocket activity, Encoded data in phishing infrastructure, Recurring phishing loaders, Stolen session cookies, Malicious redirect chains in phishing URLs

Categories

  • Email & Messaging
  • Identity & Access
  • Ransomware & Malware
  • Web Technologies